Live data from Hacker News

Scanning your iPhone for Pegasus

arkadiyt.com

31–40 of 81 posts

Re: Scanning your iPhone for Pegasus

#31
post #25

Isn't "Pegasus" transmitted via a well-crafted iMessage ? If only there was a central choke-point, globally, for all iMessage messages that could weed out particularly ill-formed messages such that they never reach your phone ... If only ...

Because of E2EE that choke point is necessarily the software update process.

Ahh... right. Thank you.

Wouldn't a simple block/allow list for sending IDs / phone numbers be trivial to implement on the iCloud (or whatever) side of things such that the end user could allow their known contacts and block (everyone else) ?

Forgive me - I am not an iMessage user ...

Re: Scanning your iPhone for Pegasus

#32
post #25

Isn't "Pegasus" transmitted via a well-crafted iMessage ? If only there was a central choke-point, globally, for all iMessage messages that could weed out particularly ill-formed messages such that they never reach your phone ... If only ...

Apple doesn't have access to the message content thanks to end-to-end encryption (technically they can have access if you backup your messages to iCloud, but by that point it's already too late).

However they are working on better sandboxing to help prevent this class of attacks, and Google Project Zero posted an overview of how that "blastdoor" process works:

https://googleprojectzero.blogspot.com/2021/01/a-look-at-ime...

Re: Scanning your iPhone for Pegasus

#33

I ran this tool and found a trace that I was infected (malware detected in CrashReporter.plist). Any clue what I should be doing, if anything, to address this?

Reach out to Amnesty Tech and/or Citizen Lab for help establishing whether this is a real infection or a false positive. If it's real: Adjust your behavior to account for the fact that once you know you're a target, there is no device on the market and no practical measures you can use to maintain safety. Assume everything you do on or near a computer used by you or a close contact is being monitored. The level of ef…

How about use your phone as only a data modem and do everything on a chrome os device, which have no known malware. Just don't install chrome extensions and you are safe. Also avoid installing apps on your phone

This is basically what I wish I had, except back in reality there's no Chrome device that's the size of my cell phone. There are some with cellular modems.

Re: Scanning your iPhone for Pegasus

#34
post #18

This is really convoluted. There is a $3 app from the App Store called iVerify that checks. [1] 1. https://www.iverify.io/

Trail of Bits hasn't shared what detections they're looking for with iVerify, but the app has extremely limited access to your device data - the device backup or full filesystem dump approaches will give you better detection.

Re: Scanning your iPhone for Pegasus

#35
post #25

Isn't "Pegasus" transmitted via a well-crafted iMessage ? If only there was a central choke-point, globally, for all iMessage messages that could weed out particularly ill-formed messages such that they never reach your phone ... If only ...

In the Amnesty report there were multiple attack vectors, one of which is via network hijacking which involves data mangling by network operators. Now it begs the question whether the network operators were in cahoots or this Pegasus is also capable of infecting network infrastructure.

Re: Scanning your iPhone for Pegasus

#36
post #31

Earlier quoted context omitted.

Because of E2EE that choke point is necessarily the software update process.

Ahh... right. Thank you. Wouldn't a simple block/allow list for sending IDs / phone numbers be trivial to implement on the iCloud (or whatever) side of things such that the end user could allow their known contacts and block (everyone else) ? Forgive me - I am not an iMessage user ...

Apple product marketing would never sign off on that because it would a) confuse their messaging by signaling that iMessage is less safe than email, b) hurt the user experience for the vast majority of customers.

Re: Scanning your iPhone for Pegasus

#37
post #7

Something like this should be available from Apple. But I guess they only offer privacy and security if it doesn’t require transparency. Well as long as it makes for good marketing.

And here I thought iOS with its walled garden approach would make these kinds of attacks impossible.

[deleted]

Re: Scanning your iPhone for Pegasus

#38
post #3

Does anyone have any info on how widespread is Pegasus?

There's the list of targets we know about: https://cdn.occrp.org/projects/project-p/#/

And the Guardian has some in-depth reporting going on. https://www.theguardian.com/news/series/pegasus-project

None of this really answer how prevalent the spyware is, though.

Re: Scanning your iPhone for Pegasus

#39
So... you're curious if your phone has government sponsored malware on it... and the solution is to image the phone and copy everything over to a different computer?? Including the possible GOVERNMENT SPONSORED MALWARE??

Don't be dumb.

Post reply on HN